We hold Siemba to the same standard we test you against.

We hold Siemba to the same strict security standards you expect from your own environment.

Your data, under Siemba
Model training on your dataNever
AI runs on your dataIn our AWS only
Free-scan data retention30 days
Post-contract export window90 days
After the windowAttested destruction
Default data residencyAWS US
EU / APAC residencyOn request
These are our standard data commitments, documented in full and available on request.
We test WebappAPINetwork CloudMobile LLM appsAI agentsMCP servers
OSCP certified CEH certified CPENT certified SOC 2 Type II MSSP certified Gartner Hype Cycle 2026 4.7 on G2

Big 4 and global consulting firms bring us in to pentest their government and enterprise clients.

Join Our Partner Program
Trusted by security teams at
MatchBook AI Curio FRONTSTEPS GravyStack Stonebranch

The vendor you bring in to reduce risk can quietly become your biggest one

Security testing is an act of trust before it's anything else. Choose the wrong partner and the very engagement meant to protect you turns into the exposure you never planned for.

Attack-level access

Pentesting means real credentials, source, and infrastructure exposure. In careless hands, that access is a breach path in its own right.

A map of every weakness

A findings report is a blueprint of exactly how to compromise you. Where it's stored, who sees it, and how long it lives should never be a mystery.

Unknown hands

Crowd-sourced and offshore models put anonymous testers inside your environment. You can't trust what you can't identify.

Security isn't a checkbox. It's the culture we operate on

A security company should be held to a higher standard than the ones it audits, not a lower one. These four commitments govern how we build the platform and how we run every engagement.

Secure by design

From architecture to deployment, prevention and validation are built into every layer, not bolted on afterward.

Transparency wins

Audit logs, risk reports, remediation timelines. Visibility builds trust, so you always know exactly where you stand.

Continuous improvement

Security is never static. We evolve, adapt, and strengthen our own posture in real time, the same philosophy our platform runs on.

Accountability

Compliance alignment and third-party validation aren't optional. We operate with integrity in every engagement, in writing.

What we promise, in plain terms

No hedging, no fine print you have to hunt for. Here is exactly how your data is handled, who touches your systems, and how we keep testing safe.

Your data

Handled on your terms, then gone

  • We never train models on your data. Your systems, findings, and traffic are never fed into model training, ever.
  • All AI runs inside our own AWS environment. Your data is never sent to a third-party model, for training or inference. Nothing leaves our boundary.
  • Your data is logically isolated from every other tenant in our multi-tenant platform.
  • Free-scan data is kept 30 days, then removed automatically.
  • After a contract ends you get a 90-day export window, followed by attested destruction of your data.
  • Data lives in AWS US by default, with EU and APAC residency available on request.
Who tests you

Named, in-house, certified

  • In-house testers only. No anonymous crowd, no offshore hand-offs. You know who is in your environment.
  • Big-4 backgrounds holding OSCP, CPENT, and CEH certifications.
  • Every tester is background-checked before they touch a customer environment.
  • Every engagement is delivered by Siemba-certified professionals, the same team behind the platform.
How we test safely

Aggressive on findings, careful with production

  • We never brute-force production systems without your explicit written permission.
  • Scope is agreed before we start, and findings are published in real time so nothing is a surprise.
  • Verified Closure: we retest every fix and confirm it actually holds, so remediation is proven, not assumed.
AI & MCP governance

Automation with a permission boundary

  • MCP access is scoped and permissioned. Any action taken through our MCP integration stays inside the boundaries you set.
  • Every automated action is logged and auditable, so an AI-triggered test is as traceable as a human one.
  • Human oversight stays in the loop on scope, targets, and anything that touches production.
Our own security posture

We hold ourselves to what we test you against

  • Siemba is independently penetration-tested by a third party. We put our own platform through the same scrutiny we bring to yours.
  • Data is encrypted in transit and at rest: TLS 1.2+ in transit, AES-256 at rest.
  • We notify you promptly of any security incident affecting your data, in line with the terms of your agreement.

Recognition that's earned, not self-declared

Third parties, auditors, and the industry have put our posture to the test. Here's the record.

Gartner® Hype Cycle™

Named a Sample Vendor for Security Operations, 2026

Recognized as a Sample Vendor in the Gartner Hype Cycle for Security Operations for 2026, following prior Sample Vendor recognition in the Hype Cycle for Application Security and Everything as a Service (XaaS) in 2024 and 2025. 2026 recognition for those two categories is pending announcement.

MSSP Alert Top 250

Global Top 250 MSSP, six years in a row

Six consecutive years on MSSP Alert's Global Top 250 Managed Security Services Providers list, reflecting sustained leadership in offensive security.

SOC 2 Type II

Audited controls across security, availability & confidentiality

An independent, AICPA-standard auditor's confirmation that our controls work over time, not a one-off snapshot. The report is available under NDA on request.

AWS Partner

Built and operated on AWS as a validated technology partner.

NVIDIA Inception

Member of NVIDIA's accelerator for AI-driven security ventures.

Georgia Tech ATDC

Portfolio member of Georgia Tech's startup incubator.

Fuel AI/ML Accelerator

Alumni of the accelerator backed by the Walton Family Foundation.

Venture Atlanta 2022

Showcased among the Southeast's top cybersecurity innovators.

GARTNER and HYPE CYCLE are registered trademarks and service marks of Gartner, Inc. and/or its affiliates in the U.S. and internationally and are used herein with permission. All rights reserved. Gartner does not endorse any vendor, product or service depicted in its research publications and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner's research organization and should not be construed as statements of fact.

Everything an audit needs, on request

Your security and procurement teams shouldn't have to chase us for evidence. Request the package and we'll share it under NDA.

  • SOC 2 Type II report: shared under NDA
  • Data Processing Agreement (DPA): on request
  • Subprocessor list: current third parties & residency
  • Security questionnaire support: we'll help complete yours

Found a vulnerability in Siemba itself? We want to hear about it. We investigate every good-faith report, keep you updated on remediation, and won't pursue action against researchers who follow the policy.

Report a security issue to:

security@siemba.io

Answers, before you have to ask

The questions security and procurement teams ask us most, answered directly.

Do you train AI models on our data?
No. Your systems, findings, and traffic are never used to train any model, ours or a third party's. All AI processing runs inside our own AWS environment, and nothing is sent to an external model for training or inference.
Can our data stay in a specific region?
Yes. Data lives in AWS US by default, with EU and APAC residency available on request. If your compliance requirements call for local data residency, let us know and we'll scope it as part of onboarding.
How is our data encrypted?
Data is encrypted in transit and at rest: TLS 1.2+ for data in transit, AES-256 for data at rest. This applies across our entire platform, not just select environments.
How long do you keep our data?
Free-scan data is kept for 30 days, then removed automatically. After a contract ends, you get a 90-day export window, followed by attested destruction of your data.
Can we see your subprocessor list?
Yes. A current list of subprocessors and their data residency is available on request as part of our documentation package, alongside our SOC 2 Type II report and DPA.
Do you help complete security questionnaires?
Yes. If you're submitting Siemba as part of a vendor security review, we'll work directly with your security and procurement teams to complete standard questionnaires and MSAs.
What happens if there's a security incident?
We notify you promptly of any security incident affecting your data, in line with the terms of your agreement. This is one of the same commitments we hold ourselves to that we test your organization against.
Is Siemba's own platform tested by anyone else?
Yes. Siemba is independently penetration-tested by a third party. We put our own platform through the same scrutiny we bring to yours, and hold a SOC 2 Type II report available under NDA.
Which privacy regulations do you comply with, like GDPR or CCPA?
Our Data Processing Agreement (DPA), available under NDA as part of our documentation package, covers GDPR and CCPA obligations for data we process on your behalf. If you operate under a specific regional privacy law, tell us and we'll confirm exactly how it applies to your engagement.
How fast will you notify us if there's a breach?
Notification timing is a contractual commitment set out in your agreement, not a best-effort promise, and can be aligned to your own regulatory obligations, for example GDPR's 72-hour reporting window where that applies. This sits alongside the same incident commitments we hold ourselves to internally.
If we leave, how do we get our data back or confirm it's deleted?
You get a 90-day export window after your contract ends, in whatever format you need, followed by attested destruction of your data. You don't have to chase us for confirmation; it's a documented step in our offboarding process.

Security you can stand behind.
A partner who never becomes the risk

See how Siemba combines an AI-native platform with certified human testers, held to the standard we hold you to.